The US government should develop (when needed) and deploy everywhere things such as OSS solutions that eliminate attack vectors like the Quark web browser (formally verified via shim verification), Hardened OSS operating systems, OSS software routing (no hidden back doors in things implementing network isolation), RSA-based authentication TFA with physical elements (and physical key pads on the secure elements for pin entry, ban internal wireless communications (no office wifi and no Bluetooth equipment), destroy equipment if it is suspected to be compromised, etcetera.
The idea would be to put mitigations into place for every imagationable attack vector by breaking everything but the things that are necessary and isolating the things that are left. That ought to make breaking into systems harder. It will likely never happen though. If anyone in charge of IT for even a portion of the US government did this, he would probably get fired as soon as those who can fire him experience proper security.
Comments
The US government should develop (when needed) and deploy everywhere things such as OSS solutions that eliminate attack vectors like the Quark web browser (formally verified via shim verification), Hardened OSS operating systems, OSS software routing (no hidden back doors in things implementing network isolation), RSA-based authentication TFA with physical elements (and physical key pads on the secure elements for pin entry, ban internal wireless communications (no office wifi and no Bluetooth equipment), destroy equipment if it is suspected to be compromised, etcetera.
The idea would be to put mitigations into place for every imagationable attack vector by breaking everything but the things that are necessary and isolating the things that are left. That ought to make breaking into systems harder. It will likely never happen though. If anyone in charge of IT for even a portion of the US government did this, he would probably get fired as soon as those who can fire him experience proper security.